How To Manage Certificates In The EUCC Framework – A Possible Approach For Assurance Continuity After The Issuance Of The Certificate (A31b)
EUCC poses new requirements to the baseline CCRA/SOGIS MRA assurance continuity procedure and makes monitoring of certificate conformity and vulnerabilities of certified products obligatory. Suspension... Read More
Where Is The Best Place To Write New Security Requirement? (A31a)
With the changes in the EU around CRA, EUCC and related security legislation that is mandating security certifications, it is becoming confusing as to where... Read More
Panel Discussion: iTC’s Lessons From The Past, Working In The Present, And Hopes For The Future (U30b)
This expert panel of iTC leads will look at how iTCs originally formed, how they have been performing, and plans for the future. The panel... Read More
Dedicated Security Components iTC Update (U30a)
The Dedicated Security Component collaborative Protection Profile (DSC cPP) plays a critical role in demonstrating up-to-date cryptographic requirements within a Protection Profile and has strong... Read More
Leveraging Common Criteria To Align With IEC 62443 (M30c)
This talk presents a structured approach to applying Common Criteria (ISO/IEC 15408) to railway industrial control systems, aligning with IEC 62443-4-1 secure development practices and... Read More
Adressing The Real World: Challenges In Defining A WSCA Protection Profile For An Existing Ecosystem (M30b)
CEN TC 224 WG17 is developing a Protection Profile (PP) for Wallet Secure Cryptographic Applications (WSCAs) within the framework of the European Digital Identity (EUDI).... Read More
Architecture-Aware Packages For High-Assurance Physical Security (M30a)
Physical security is a foundational requirement for high-assurance (e.g. EAL6) TOEs that must withstand sophisticated physical and fault-injection attacks. Effective protection arises from a coordinated... Read More
Improving CC Evaluation Efficiency Through MAL (A30c)
Threat modeling identifies potential vulnerabilities, improving Common Criteria (CC) evaluation objectivity and consistency. By automating threat modeling, CC evaluations reduce time and cost while becoming... Read More
Enhancing Vulnerability Assessment In Common Criteria Through Threat Centric Models (A30b)
CC evaluations often lack resilience against APTs, zero-days, and AI-assisted attacks due to VA models and the level of assessment assumptions. This paper critiques current... Read More
Thinking Backwards. A Proposal From CB Perspective For AVA Continuous Improvement (A30a)
AVA activities should be based on a comprehensive analysis of TOE documentation. “Backwards ” tracking of the activities conducted by the laboratory for the AVA_VAN... Read More